Hello, I'm going to Configure HA active-active but currently I have SD-wan "5 members" with multiple IPSec VPN & my question about 1 - Could I connect each Fortigate directly to the router or via Switch ?
2- If I use a switch between HA & routers? in this case how to configure Static(public) IP ? 3- Regarding IP-SEC VPN it will be configured on the primary device only ? right , Due to Endpoint gateway IP so no load balance for VPN.
1 - Could I connect each Fortigate directly to the router or via Switch ?
that depends on the router, if the router has a build-in switch port you could do this. If the Router has only 1 LAN port, then you need a switch to connect 3 ports to the same Layer-2 domain. Be careful not to use 1 switch to connect all routers and FTG’s together even when using VLAN’s per connection, because you will introduce a single point of failure, the switch.
2- If I use a switch between HA & routers? in this case how to configure Static(public) IP ?
In Active-Active you only configure the Primary Fortigate, the config will be synchronized to the Secondary, so except the HA settings the config will be the same.
3- Regarding IP-SEC VPN it will be configured on the primary device only ? right , Due to Endpoint gateway IP so no load balance for VPN.
Yes once the HA config is done and the Fortigates are Up and in sync, you only configure the Primary FTG.
In HA Active-Active the following sessions are processed by the primary unit & not load balanced: UDP, ICMP, Multicast, Broadcast, VoIP, IM, P2P, IPSEC VPN, HTTPS, SSL VPN, HTTP Multiplexing, SSL Offloading, WAN Optimization, Explicit Web Proxy & WCCP sessions.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.